GPEN Escalation and Exploitation Practice Question
During an internal assessment, you gain a foothold as a low-privileged domain user on a Windows Server 2019 host that is a member of an Active Directory domain. You run whoami /priv and observe SeImpersonatePrivilege enabled in your token. You need to escalate to NT AUTHORITY\SYSTEM on this host. Which technique is most appropriate?
⚠ Common exam trap
The trap here is assuming any Potato tool works on any Windows build, when patched builds like Server 2019 require PrintSpoofer or RoguePotato instead of the classic JuicyPotato CLSID abuse.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Abuse SeImpersonatePrivilege with a token impersonation tool such as JuicyPotato, RoguePotato, or PrintSpoofer, depending on the OS build.
SeImpersonatePrivilege allows a process to take on the security context of a token it receives, and privileged Windows services can be coerced into connecting to an attacker-controlled listener. Tools such as PrintSpoofer and RoguePotato exploit that behavior to obtain a SYSTEM token on modern Windows builds where older Potato techniques no longer work. Because the privilege is already present in the token, this is the direct escalation route.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Run a Kerberoasting attack against all service accounts and crack the resulting RC4 hashes offline to obtain a domain administrator password.
Why it's wrong here
Kerberoasting requests service tickets for accounts with SPNs and cracks them offline, which can yield service account credentials, but it produces domain credentials rather than SYSTEM on the local host. It also depends on crackable password strength and gives no guarantee of local administrative context on the server you already control.
- ✗
Extract cached domain credentials from the registry using reg save on the SAM and SYSTEM hives and crack them with hashcat.
Why it's wrong here
Saving the SAM and SYSTEM hives yields local account hashes, and those hive files are normally readable only by administrators. A low-privileged user cannot read them, so this path fails before cracking even begins. It also targets local account credentials, not the SYSTEM token escalation that SeImpersonatePrivilege enables.
- ✓
Abuse SeImpersonatePrivilege with a token impersonation tool such as JuicyPotato, RoguePotato, or PrintSpoofer, depending on the OS build.
Why this is correct
SeImpersonatePrivilege lets a process impersonate a token handed to it by a client, and tools like PrintSpoofer or the Potato family coerce a SYSTEM-privileged service into authenticating so the token can be captured and reused. On Server 2019 the classic JuicyPotato CLSID path is patched, so PrintSpoofer or RoguePotato is the working variant here.
- ✗
Perform an unquoted service path attack by placing a malicious executable in a directory whose path contains a space and is writable.
Why it's wrong here
Unquoted service path abuse requires a service configured with an unquoted path containing spaces and a writable parent directory. Nothing in the scenario indicates such a misconfigured service exists, and the presence of SeImpersonatePrivilege in your token already points to a far more direct and reliable impersonation-based escalation path.
About these practice questions
One of 298 original GPEN practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.